managing-bibliography
Warn
Audited by Snyk on Mar 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). SKILL.md explicitly instructs downloading and reading arXiv LaTeX sources (e.g., the "Download arXiv LaTeX source" curl example https://arxiv.org/src/2503.19441) and querying ADS for BibTeX, so untrusted public third‑party content from arXiv/ADS is ingested and used to drive citation generation and file-modifying actions.
Audit Metadata